THE SHORT ANSWER
Account takeover means an unauthorized person controls an account. They may impersonate its owner, reset connected services, change recovery details or send fraudulent requests. Recovery includes securing the account, reviewing sessions and recovery methods, revoking access and warning affected contacts.
One account can be a trust and recovery hub
- Email can receive password-reset links.
- Messaging and social accounts can impersonate the owner.
- Business accounts can expose customer or operational access.
- Admin accounts can affect many connected users and services.
Recover through the provider's official process
Use a trusted device where possible, change compromised and reused credentials, review recovery email and phone details, revoke unfamiliar sessions or connected apps, and enable the strongest suitable MFA or passkey option. If access is lost, start with the provider's official recovery page.
Evidence & context: United States Federal Trade Commission
Repair the trust channel too
Tell affected contacts through another channel when fraudulent messages may have been sent. For a business account, preserve records and involve the responsible security or IT contact. Do not quietly restore access while leaving recipients to act on earlier messages.
Use the Cybersecurity module for protective controls
Read Passwords, Passkeys & Multi-Factor Authentication and How to Protect Business Accounts & Admin Access for deeper account controls.
Evidence & context: National Institute of Standards and Technology
Sources & further reading
- How To Recover Your Hacked Email or Social Media Account
United States Federal Trade Commission. Defensive account-recovery guidance including reviewing recovery details and warning contacts after compromise. Exact recovery controls depend on the platform.
- NIST SP 800-63-4: Digital Identity Guidelines
National Institute of Standards and Technology. The 2025 guideline distinguishes identity proofing, authentication and federation and selects assurance according to risk. It is written for United States federal systems but offers a useful conceptual reference beyond them.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗